Call us: 10am – 6pm ET

888 540-2010, 416 833-3501

Imaging to a file on an encrypted drive with TaskForce

With newest Atola TaskForce 2020.1 firmware, it is possible to image into files on an encrypted target drive using VeraCrypt for data encryption. Multiple target drives can be encrypted for the same or different sessions.
After you have connected the source drive to a port in Source mode, take these steps:

1. Click on Image icon in the left-side taskbar
2. In Select source device panel, select the evidence drive
3. In Select target device menu, click on the tile in the File section
4. In Select image file window, click Add storage Click the link Create Image File on Target.

5. In Select device panel, choose the drive connected to a port in Target mode
6. Select Create an encrypted VeraCrypt container (exFAT) option and click Next

7. Enter and confirm the password for the encrypted volume on the drive

8. Confirm the formatting of the device by entering YES and clicking OK. After this step, the formatting will take a few seconds.
9. Click + Create file button
10. Enter the name of the image and choose the file format (E01, raw, img or dd).

11. Once you have created the file, you may add more image files in the same or a different folder

After you click the Continue button, TaskForce will image the evidence into the file on your encrypted target.

Upon completion of the imaging session, check the Imaging completed report. 

Data Extraction

  1. To find the VeraCrypt volume and the imaged file, plug the target drive into your computer;
  2. Use VeraCrypt software to safely access encrypted data from your drive;
  3. Select the drive label (A, B, C, etc.) on which you want the volume to be mounted;
  4. Click Select device button;
  5. In the pop-up window select your encrypted volume;
  6. Click the Mount button. 

Now you can view the partition name, size and encryption algorithm.

7. Next, use the password set prior to the imaging session to get access to the encrypted volume.

Once you have entered the password, the volume will be mounted and you can access it from Windows Explorer and use the image for subsequent operations.